Why Email Is Still the Most Common Entry Point
Despite decades of awareness, email remains the starting point for around 90% of cyber attacks. The reason is straightforward: email is the primary communication channel for almost every business, which means every employee with an inbox is a potential target. Attackers do not need to find a technical vulnerability in your systems if they can simply trick a member of staff into clicking a link or opening an attachment.
Email-based attacks have grown more convincing over time. AI tools allow attackers to generate personalised, well-written messages at scale. Spoofed sender addresses, lookalike domains, and stolen branding make fraudulent emails increasingly difficult to distinguish from genuine ones on a quick read.
The Main Threats That Start in the Inbox
Phishing
A phishing email impersonates a trusted source, such as a bank, supplier, or colleague, to trick the recipient into handing over login credentials or clicking a malicious link. The fake login page that follows is designed to capture whatever the user enters. Once credentials are stolen, the attacker has legitimate access to your systems.
Malicious attachments
Emails containing infected attachments, whether Word documents, PDFs, or ZIP files, deliver malware directly to the recipient’s device when opened. Some techniques, such as deliberately corrupted files that Word automatically repairs, are specifically designed to bypass email security filters.
Business email compromise
An attacker impersonates a senior colleague or supplier to request an urgent payment or change of bank details. These attacks rely on urgency and authority rather than technical trickery. They are among the costliest forms of email fraud because the transfer often happens before anyone realises something is wrong.
Ransomware delivery
Many ransomware attacks begin with a phishing email that delivers an initial payload. Once executed, the malware spreads through the network, encrypting files before the attack is detected. The email is the entry point; the ransomware is what causes the damage.
Reducing Your Email Risk
Email filtering and anti-spoofing controls
Properly configured email filtering blocks known malicious senders, scans attachments, and flags messages from domains that are impersonating legitimate businesses. SPF, DKIM, and DMARC records reduce the ability of attackers to spoof your domain and prevent others from spoofing domains you trust.
Multi-factor authentication
MFA means that stolen email credentials alone are not enough to access your accounts. Even if a staff member’s password is captured via phishing, the attacker cannot log in without the second factor.
Staff training
Technical controls reduce the volume of malicious emails that reach your team but they do not eliminate it entirely. Staff who know what to look for, how to verify unexpected requests, and when to report something suspicious provide a critical last line of defence.
Clear payment verification procedures
Business email compromise attacks are stopped by process rather than technology. A simple rule that all payment changes or urgent transfer requests must be confirmed by phone call before being actioned prevents the most common and costly form of email fraud.
The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.